Get notified of our articles as they're available
Your data is safe - no sharing, no spam.
PocketOS lost its production database and associated backups after a Cursor agent powered by Claude located an API token in a file and used it to delete the Railway volume holding the data. The incident is most useful as a credential governance failure: a token intended for limited operational use was discoverable, broadly permissive and apparently persistent enough to remain available for misuse.
iam data loss
CERT-EU attributed the European Commission cloud breach to TeamPCP, which used a compromised AWS API key stolen in the Trivy supply-chain attack to access the Commission’s Amazon cloud environment and exfiltrate data affecting up to 71 Europa web hosting service clients.
aws s3 data loss
Grafana confirmed its breach stemmed from a compromised CI/CD environment after malicious TanStack npm packages exfiltrated GitHub workflow tokens and one token missed during rotation was later used to access private repositories.
iam cicd
A copy of the Mexican National Electoral Institute voter database containing 93 million records was exposed from a MongoDB deployment on Amazon EC2 after being left reachable from the internet with no authentication and no encryption.
aws ec2 data loss
Microsoft disclosed an incident where a blob storage URL containing an overly permissive Azure Shared Access Signature token was posted by an employee in a public GitHub repository, allowing Wiz to access internal data in a Microsoft storage account.
iam azure
Railway’s reported outage of their entire platform in 2026 is best understood as an operational dependency failure with direct security and governance implications. The core lesson is not a classic intrusion scenario, but the concentration risk of running a business on a single cloud provider account that can be suspended or deleted, taking the product offline with it, especially where that cloud provider is known for ad hoc account deletion.
gcp multi-cloud
Cisco Talos reported that UAT-10608 exploited the React2Shell vulnerability, tracked as CVE-2025-55182, to gain remote code execution on publicly reachable Next.js applications and harvest credentials at scale across at least 766 hosts.
waf software
ADT confirmed unauthorised access to customer and prospective customer data after detecting the intrusion on April 20 and later determining that personal information had been stolen. The key aspect is not just that data was taken, but that a reportedly single vishing event against an employee’s Okta SSO account may have provided a path into Salesforce, showing how one compromised identity can traverse linked enterprise systems and expand blast radius quickly.
sso iam
Poland’s railway disruption demonstrates a core control failure: safety-critical operational commands were accepted without authentication or authorization, allowing unauthorised actors to trigger emergency stops with cheap radio equipment.
iam
Whilst this incident only affected smaller hobby accounts both scenarios identify a clear cloud security failure pattern: public Google Maps API keys are intentionally exposed to browsers, yet they can create unnecessary blast radius when reused inside GCP projects that also enable Google services intended for non-public or back-end usage.
gcp iam
Mazda left an old database originally from an acquisition available for compromise via direct internet exposure
data loss old data acquisition